Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Pfc200 Firmware HIGH 7.2
CVE-2019-5156

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and…

No fix yet
Fix from $1,950 2020-03-11
Pfc200 Firmware HIGH 7.2
CVE-2019-5157

An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07…

No fix yet
Fix from $1,950 2020-03-11
Blamer CRITICAL 9.8
CVE-2019-10807

Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided …

Fix: 1.0.1+
Fix from $2,300 2020-03-11
Pan Os HIGH 7.8
CVE-2020-1980

A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. T…

Fix: 8.1.13+
Fix from $1,950 2020-03-11
Vesta Control Panel HIGH 8.8
CVE-2019-9859

Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the…

Fix: after 0.9.8-23
Fix from $1,950 2020-03-10
Direx Pro Firmware CRITICAL 9.8
CVE-2020-10250

BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.

No fix yet
Fix from $2,300 2020-03-09
Cryptomove HIGH 8.8
CVE-2020-2159

Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the…

Fix: after 0.1.33
Fix from $1,950 2020-03-09
Froxlor HIGH 8.8
CVE-2020-10235

An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via th…

Fix: 0.10.14+
Fix from $1,950 2020-03-09
Kace Systems Management CRITICAL 9.8
CVE-2019-20504EPSS 10%

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell …

Fix: 6.4.120822+
Fix from $2,300 2020-03-09
Dcs 930l Firmware HIGH 7.2
CVE-2016-11021 KEVEPSS 69%

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

Fix: 2.12+
Fix from $1,950 2020-03-09
Rconfig HIGH 8.8
CVE-2020-10221 KEVEPSS 37%

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the…

Fix: after 3.9.4
Fix from $1,950 2020-03-08
Dir 825 Firmware HIGH 8.8
CVE-2020-10213

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10215EPSS 5%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10216EPSS 5%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s…

No fix yet
Fix from $1,950 2020-03-07
Centreon HIGH 8.8
CVE-2019-17642

An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac…

Fix: 18.10.8 / 19.04.2+
Fix from $1,950 2020-03-05
Vr 3033 Firmware HIGH 8.8
CVE-2020-10173EPSS 77%

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and tracerout…

No fix yet
Fix from $1,950 2020-03-05
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20499EPSS 95%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the …

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20500 KEVEPSS 97%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web…

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20501EPSS 90%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web i…

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Nas326 Firmware CRITICAL 9.8
CVE-2020-9054 KEVEPSS 100%

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi…

Fix: 4.35 / 5.21+
Fix from $2,300 2020-03-04
Remote Phy 120 Firmware MEDIUM 6.7
CVE-2020-3176

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of…

Fix: 7.7+
Fix from $1,600 2020-03-04
Openblocks Iot Vx2 Firmware HIGH 8.8
CVE-2020-5535

OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary OS commands with root privil…

Fix: 4.0.0+
Fix from $1,950 2020-03-04
Ansible Engine HIGH 7.4
CVE-2020-1734

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=…

Fix: after 3.3.4
Fix from $1,950 2020-03-03
Wnr1000 Firmware CRITICAL 9.8
CVE-2019-20488

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to com…

No fix yet
Fix from $2,300 2020-03-02
Push Dir CRITICAL 9.8
CVE-2019-10803

push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being …

Fix: after 0.4.1
Fix from $2,300 2020-02-28
Serial Number CRITICAL 9.8
CVE-2019-10804

serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function …

Fix: after 1.3.0
Fix from $2,300 2020-02-28
Enpeem CRITICAL 9.8
CVE-2019-10801

enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.

Fix: after 2.2.0
Fix from $2,300 2020-02-28
Giting CRITICAL 9.8
CVE-2019-10802

giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package witho…

Fix: 0.0.8+
Fix from $2,300 2020-02-28
Kill Port Process CRITICAL 9.8
CVE-2019-15609

The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.

Fix: 2.2.0+
Fix from $2,300 2020-02-28
Centreon HIGH 8.8
CVE-2020-9463

Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an …

No fix yet
Fix from $1,950 2020-02-28